9 ms·
1Password to Add Telemetry
- adoxyz 3y agoI've been a 1Password customer for many years. Their product is super solid. The family plan is very generous. I personally don't have an issue with them collecting some telemetry to improve the product. And they've stated they'll offer ways to opt-out.
- closewith 3y agoI'd accept making it opt-in, but opt-out is ridiculous. I can't imagine how they're going to get this past EU regulators. I love (although loved more in the past) 1Password and have deployed it in two separate companies. Between this and recent UI updates (well, over the last couple of years), maybe it's time to look at alternatives.
- Negitivefrags 3y agoIf you don’t collect any identifiable data, then the EU has nothing to say about it.
- closewith 3y agoUnless they have a non-IP based communication system, then they'll fall afoul of the same thing all online analytics services do - they'll be collecting, at least ephemerally, personal data under the EU definition.
- Negitivefrags 3y agoIt is my understanding that if you do not log the IPs that connect, then you are not collecting personal data.
- closewith 3y agoLast year, a German court fined a website for using Google Fonts as it was providing the IP address to Google without authorization and without a legitimate reason for doing so. It seems likely that the same reasoning will apply here.
- abigail95 3y agoWhat about anonymous logging of which buttons people click on is illegal in the EU? Citation needed on this one. That would make any dashboard that showed which api endpoints are the most popular also illegal. Anomyous telemetry is not PII. GDPR is personal data.
- nness 3y agoAs long as there's no "session identifier," even if unique and completely unmarriable to the PII, it doesn't matter. Any session ID where an ID represents one person runs afoul. Makes meaningful telemetry really hard without consent. Everyone just consents anyway...
- abigail95 3y agoMy position is they can indeed get meaningful telemetry with opt-out anonymised data and that the GDPR does not prevent this. I am countering the position of the parent poster and asking for a citation that would indicate you don't need to sneak this around the EU regulators to do it.
- alpaca128 3y ago> Everyone just consents anyway... Unless you don't lie to them and don't use every dark pattern in the book to trick them into clicking the checkbox.
- JohnFen 3y ago> Anomyous telemetry is not PII. That depends. First, no data collection is "anonymous" when it is transmitted. Any anonymity must come later, and then is only possible if the company aggregates the data with other users and deletes the original data that was collected. PII/Personal Data are squishy terms. In the US, anyway, the legal definitions of what counts as "PII" leaves out an awful lot of actual PII -- so any claims that "no PII is being collected" is meaningless without additional explanation of what data items are being collected.
- abigail95 3y ago
- bwoodruff 3y agoI wrote more about the consent aspect here: https://news.ycombinator.com/item?id=35706897 https://news.ycombinator.com/item?id=35706897 tl;dr If we roll this out to customers, we'll be asking for consent, and won't be collecting telemetry data unless we have it. -Ben, 1Password
- closewith 3y agoThat's much more reasonable than the wording on the linked page. Thanks for your response.
- bwoodruff 3y agoHappy to help. In addition, while we're in the early stages and this design is likely to change, it may help to visualize how we're thinking about this process: https://bucket.agilebits.com/ben/telemetry-consent-draft.png https://bucket.agilebits.com/ben/telemetry-consent-draft.png
- version_five 3y agoIt's enough to make me at least look for alternatives. If I'm paying for something, I'd strongly prefer to do so on my terms. I use Microsoft office in spite of the fact that it's basically just an industrial spying platform, because I don't have any other options. If I can find a password manager that's easy to switch too that doesn't spy on me, I'll do so. We shouldn't be rewarding companies for this.
- webworker 3y ago> industrial spying platform Applies to much more MS products than just Office these days. I personally stopped being able to justify Office when they moved to subscription and iWork moved to bundled and already installed. I still have Office on my work Mac and boy is it laggy typing as it analyzes the words and sends them to who knows where.
- mdaniel 3y ago> Their product ~~is~~ used to be super solid. Don't get me wrong, it's still light years ahead of the Bitwarden clients and extensions, and that's why I stay, but I for sure would not use the present tense for their quality
- arepublicadoceu 3y ago> it's still light years ahead of the Bitwarden clients and extensions I’m quite possible a simpleton but I can’t see how it’s light years ahead of Bitwarden. Can you provide an example of such difference? Every time I used to check 1password (before the Great Purge of local vaults) I always arrived at the same conclusion. It’s a bit more beautiful but not 3x or 4x (whatever the price is) more beautiful then Bitwarden. Functionality wise I couldn’t see much of a difference. Both save passwords, both share passwords, both generate passwords and both have Totp support.
- mdaniel 3y agoI often regret any contact I have with the Bitwarden fanbase, because whooo they are rabid, but I guess I used to be a rabid fan of 1P so maybe fair's fair :-D Anyway ... - https://github.com/bitwarden/clients/issues/1620 https://github.com/bitwarden/clients/issues/1620 was created 2021, after it was migrated from the issue that was open even longer in the other repo, and now they've locked the issue because they're tired of people complaining about the extension losing their credentials - there are a ton more Item types in 1Password, which some people consider just cosmetic ("you can create your own fields") but https://bitwarden.com/help/managing-items/ https://bitwarden.com/help/managing-items/ compared to https://support.1password.com/item-categories/ https://support.1password.com/item-categories/ is night and day, setting aside the native support for SSH agent that's built into 1P nowadays and here starts the list of even more highly subjective items, which I acknowledge are highly subjective - the folder based item management in Bitwarden is highly inferior to the tags based management in 1P. Creating folders itself is a major PITA, whereas creating tags in 1P is ... just type the new tag name. Maybe people enjoy putting the "tags" in there item's names or whatever, and doing away with folders in Bitwarden, but ... the fact they're trying to implement tagging on the cheap indicates they want tags but Bitwarden doesn't see the world that way - I find the attachment management process cumbersome in Bitwarden, whereas in 1P there are actually two orthogonal ways of managing attachments: they can be first class Items (called "Document" items) meaning that is the whole secret that one would care about, and they can also be arbitrarily attached to other Items in kind of a supporting role. I have scans of my passport attached to the Passport item type because so many places ask me to upload a scan of my passport. Same for my driver's license on the formal Driver's License item type - in the theme of "finding it cumbersome," I find that 1Password seems to care a lot more about UX than Bitwarden. Now, of late I am having to qualify any such statement because yikes that 1P 8 rewrite was catastrophic. But, rewrite-induced-self-inflicted-harm aside, I still think 1P cares a lot more about UX than Bitwarden - also subjective, but I really enjoy the `op run` <https://developer.1password.com/docs/cli/reference/commands/run https://developer.1password.com/docs/cli/reference/commands/...> and its ability to resolve specially formatted env-vars <https://developer.1password.com/docs/cli/secret-references https://developer.1password.com/docs/cli/secret-references> in the sub-process. That process seems to be the basis of their shell plugins system <https://developer.1password.com/docs/cli/shell-plugins https://developer.1password.com/docs/cli/shell-plugins> but TBH I find just having env-vars lying around to be more convenient than their shell plugin system for my workflow. The fact that the `op` binary is smart enough to use DBus to auth to my desktop session means I can also use it as an implementation of pinentry A perfectly reasonable question may be "well, it's open source, why not start fixing bugs?" The things about using folders and the lack of item types indicates to me that they're just rowing in a different direction than what I would like, and the fact that they're a commercial company means unless I directly would benefit from fixing a bug means I am not incentivized to contribute free labor
- JohnFen 3y agoWhile I am very allergic to such data collection, if you're going to do it, this seems like the way to do it. I'm not a 1Password user (and won't become one), but if I were, I wouldn't necessarily be in a huge rush to stop as a result of this.
- musicale 3y agoI wouldn't object to Apple driving another small nail into 1Password's coffin by coming up with a scheme to enable Firefox and Chrome to access iCloud Keychain for certain web site passwords (but not all of them!) Supporting it on Windows could be another nail.
- nikanj 3y agoAfter taking in ridiculous amounts of money, they must figure out what features are most crucial for users – so that those features can be monetized the hardest
- hammyhavoc 3y agoOr so they can ditch lesser used features to eliminate technical debt.
- ValentineC 3y agoRelevant xkcd: https://xkcd.com/1172/ https://xkcd.com/1172/
- Tagbert 3y agoWhere are those "ridiculous amounts of money"? The price of 1password seems very moderate so they must selling enormous number of licenses to amass so much money.
- detaro 3y ago2022: "1Password with $620M Series C, now valued at $6.8B" https://techcrunch.com/2022/01/19/1password-series-c-funding/ https://techcrunch.com/2022/01/19/1password-series-c-funding... (following a $200M Series A and a $100M Series B in 2019/2021)
- nikanj 3y agoHence the ”must monetize” part. The investors expect to wring at least 5x their money, and selling $49 lifelong licenses does not net you billions
- xyzzy_plugh 3y agoSeems fine to me. Opt out is reasonable, I trust 1password to not fuck this up versus, say, LastPass. If you already trust 1password to store your credentials, I see little to no impact to your risk exposure by having them collect anonymized telemetry. Curious if others have thoughts here? Their UI has changed a lot in recent years, maybe this will enable them to make more informed design decisions so that one day grandparents stop getting lost in their horrible menus.
- AlexandrB 3y ago> If you already trust 1password to store your credentials I don't, so I'm never upgrading to 1Password 8. The telemetry news only validates my decision. What I consider important in a security product and what AgileBits considers important diverged a while ago and that's ok I guess.
- dijit 3y ago1password 8 definitely feels like a massive UX downgrade over v7. Though I can’t put why into words.
- flinner 3y agoThe latest version seems optimized for keyboard shortcuts at the expense of easily accessible 1-click copying of username/password/one-time password. To me, this introduced a large additional cognitive load where instead of a click, click, click, I now have to remember that CMD+C is username, CMD+Shift+C is password, and (something else?) for One-Time Password.
- kitsunesoba 3y agoI think it's that v8 feels less an app crafted for individuals and more like yet another generic SaaS made for corporate customers.
- pinkcan 3y agoit's no longer a native app
- nickvanw 3y agoI have my issues with what 1Password has become as a product, but this seems like a very good stance to take. As a product owner, it's essential to know what and how people are using the product, collecting some straightforward telemetry that's anonymized and doesn't contain and Vault data strikes me as reasonable.
- favorited 3y agoIf it is so essential, how have they been so successful since 1P was released nearly 20 years ago?
- d1l 3y agoThey didn't have an army of UX fuccbois back then. Now they do and this is an endless stream of makework to justify themselves.
- illiarian 3y ago> As a product owner, it's essential to know what and how people are using the product You can ask the users. You can apply some common sense (which 1Password team increasingly doesn't). They can look at the support forums listing the many issues (especially with UX) which are condescendingly dismissed. Etc.
- imwillofficial 3y agoThis is exactly what I want in my password manager.
- waynesonfire 3y agoabsolutely. i hope they don't charge more for this feature. hell, why stop at 1password properties? leave no stone unturned, there may be other secrets laying around that can monetized with innovative product features to ensure the IPO is a success for the investors.
- danpalmer 3y agoTelemetry to inform product decisions is fine, in fact I think it's necessary to have confidence that software is performing in the wild (e.g. crash reporting), or that customers know how to use it. What is not ok is opt-out telemetry for personalisation for advertising, or over-reaching personal data collection, in 1Password's case data from your vault. There is however a grey area in the middle – data about the performance of product upsells. This is a tricky one, because arguably if I do upgrade (say, to 1Password Family/Teams), I've probably done so because it made sense for me, and I'm probably happier with the product... but I might not have done so without that information on how I or others use the product that helped optimise that flow. When done well I don't have a problem with this, but I hope 1Password are careful about the culture of upsells that this data could create.
- TechBro8615 3y agoThe worry about telemetry in a product like this is how it's implemented. It's more code that could have bugs in it. What assurances do we have that it will execute safely in a way that it can't possibly access the password database, even in the event of (for example) compromise of the CI pipeline that builds the telemetry SDK? > No customer vault data can be seen or collected. We’re only interested in how people use the app itself, what features and screens they interact with – not what they store in their vaults, what sites they autofill on, or anything like that. This seems contradictory to me. How can the code see what screen is open without interacting with the app? This implies there is some kind of sandboxing layer. How can the 1Password software engineers possibly be confident enough in this sandboxing to assert that "no customer data can be seen?" That may be their intent, but bugs happen, especially in code that runs at a layer above the app to analyze how users interact with it. I will be opting out. Hopefully the opt-out mechanism doesn't have a bug in it either. And when there is inevitably a bug in the telemetry, I hope 1Password is okay with admitting that their opt-out system created two classes of users: those who did nothing, and thus remained vulnerable to bugs in the telemetry layer, and those who opted out of it.
- 1123581321 3y agoThey do separate the UI application from the kernel that manages access to the data. I guess the biggest risk would be that you click reveal, which has the kernel expose a password to the UI, and then the UI phones home with its entire raw contents.
- deleted 3y ago[deleted]
- nullstyle 3y agoI'm disappointed with what 1password has become. To put it in a tone I feel is appropriate given how much time and money I've invested into their product, I don't think abandoning native development for electron to shove telemetry into your product counts as bending over backwards to preserve privacy. It reeks.
- nullfield 3y agoWhich is why they just got told to cancel my future renewals, giving me like… 10-ish months to move stuff to something I actually control, unless they figure out a less stupid plan. If I have to fight with a product to block telemetry, I’m not going to have it be one I’m paying them for like this, and I’ll take every company I can with me.
- wootland 3y agoOpt-out telemetry is unacceptable, this also signals that the product team has no vision and the organization is riddled with bureaucracy. Great products get built by someone with a vision to create them, mediocre products gets created by product managers justifying their positions with data they've gleaned by spying on users.
- ninkendo 3y ago100% agreement from me. People have trouble believing this, but software existed before telemetry existed. We didn’t have trouble understanding where user pain points were back then, because we actually performed user studies, and offered the ability for users to provide feedback if they wanted to. The field of UX wasn’t born the moment someone wrote the first telemetry library.
- marcosdumay 3y ago> We didn’t have trouble understanding where user pain points were back then If anything, people seem to have much more difficulty understanding user pain points right now.
- WirelessGigabit 3y agoBecause of telemetry we know what brings in the most money. So while telemetry might show that moving an item from one group to another (just making something up) takes > 1s, fixing this will not bring in $. So when we then do Sprint Planning all of that gets pushed to the ice box.
- marcosdumay 3y agoThis already starts from a big mistake, because telemetry can't tell you the value of any work you haven't done yet. The question whether it can tell you the value of anything at all is a hard one that needs plenty of context, and nobody seems interested on answering. But your reasoning doesn't need this answer.
- johnla 3y agoAt risk of sounding dumb: what's in the telemetry data?
- latexr 3y agoThe post only mentions a few things: > we’ll be able to gather only a small set of general events and interactions within our apps. Things like when you unlock the app, when you create a new item (but not its contents!), or when you use autofill (but not what sites you use it on!).
- ehPReth 3y agocall me stupid; but I'm not sure how those numbers are helpful for them?
- deleted 3y ago[deleted]
- selykg 3y agoHow are people creating new items? App, or extension? How are people accessing items? App, quick access menu, extension, browser bookmark? How are people changing passwords? In the app, using the password generator or not, in the extension with the password generator, in the browser using the injected UI? The thing about 1Password is that it seems like it's simple, but under it all there's usually multiple ways to do the same thing. Using some telemetry they could easily see that only 2% of users are using this one particular feature, and cut it if it's not getting used. Or this fantastically useful feature is only getting 20% of users using it, maybe they need to introduce it to users in a better way. Etc. At the end of the day, having this kind of data can make for better decisions. I'm not a fan of telemetry though. I'm honestly surprised the security team at 1Password agreed to this one as well.
- latexr 3y ago> having this kind of data can make for better decisions. It can also make for worse decisions. 2% of millions of users is still tens of thousands of people. Maybe that feature is terribly useful but only a handful know about it. Cutting it would be a mistake; it should be made more prominent. Maybe the 20% feature is annoying and that’s why 80% of people actively avoid it. Giving it more prominence would be a mistake; it should be cut. No amount of telemetry will tell you users are deeply unhappy with the move to an Electron app and the removal of local vaults. You only know that from direct feedback and speaking to them.
- oefrha 3y agoIf telemetry can tell them 1Password 8 UX is a downgrade from 7, I’m all for it.
- myhf 3y agoWhat would they even do with that information? “It is difficult to get a man to understand something, when his salary depends on his not understanding it.” - Upton Sinclair
- robbiep 3y agoThe vc funded slide into oblivion started a while ago and continues
- favorited 3y agoThe slide into Enterprise™, you mean. Lots of big companies use 1Password as an IT solution for secrets management. That $6.8 billion valuation has to come from somewhere.
- pinkcan 3y ago[flagged]
- tptacek 3y agoThe only reason we're talking about this is that 1Password wrote a blog post about it. They're not dumb, they know that this is the reaction they can expect from a blog post about how they're doing telemetry. They compete with a raft of products that not only use telemetry, but do it sneakily and with SAAS vendors that add attack surface to their products. But nobody talks about telemetry in those products, because those vendors don't want to have the conversation.
- JohnFen 3y ago> But nobody talks about telemetry in those products Sure they do, and a lot. But they don't talk about with with the companies doing it. What would be the point?
- moaf 3y agoExactly. Just look at Bitwarden's privacy policy, for example: > We use data for analytics and measurement to understand how our the Site and Bitwarden Service are used. For example, we analyze data about your visits to our Site to do things like optimize product design. We use a variety of tools to do this, including Google Analytics. When you visit the Site using Google Analytics, we and Google may link information about your activity from that site with activity from other sites that use Google Analytics services.
- bwoodruff 3y agoI was an advocate for putting out the blog post early, despite the fact that we're currently only testing this with our employees. As you say, we knew it would be something the community would have questions about, rightfully so, and wanted to be as transparent as possible. -Ben, 1Password
- TkTech 3y agoMy history with 1Password: - Purchase a stand-alone license, getting well-performing and feature-complete native clients with several options for vault sync that are under my control. - Upgrade to 1Password 8, a version that sounds great, but has quietly removed local sync unless you checked forum and blog posts before buying. - Watch the clients go from being native to Electron and losing many, many features. Get forced into using the web app for simple things like seeing history. - Watch browser integrations get progressively worse (check out the reviews on the Firefox extension, oh boy) - Even if you've been using 1password 7 (the version you paid a good chunk of change on for, in 1Password's own words, a life-time license), you won't be able to use it with browsers at all soon https://support.1password.com/kb/202303/ https://support.1password.com/kb/202303/. - Get popups and unwanted opt-out integration with social media logins, when I've gone out of my way to purge garbage like "login with google" from my internet experience. - Get unwanted opt-out telemetry forced on you, which regardless of their assurance will eventually leak PII like it always does. People make mistakes, c'est la vie. I would have no issue with opt-in telemetry. I think this is it for me. Forced telemetry is a small thing, but it's just one of many poor decisions. I'm sure it's a smart business decision and their investors will be happy finding more and more ways to extract value out of users. I just want a simple password manager, so after a decade this is it for my family and myself.
- ploum 3y agoMigrated to Bitwarden for the opensource years ago. Stayed for cheaper price, linux support, simplicity and "out of my way" philosophy. Never looked back to 1password.
- Night_Thastus 3y agoSame, though I just use the free Bitwarden, not sure what the paid one provides. It's been good. Very simple and reliable. Has barely changed in years of use and hasn't needed to.
- stronglikedan 3y agoI pay them for the TOTP authentication alone, so that I don't have to never ever use google authenticator ever again, but it also feels good to be able to support such an awesome project, even if it's only a little.
- tohnjitor 3y agoI dropped 1P the day I ran a suggested update and it locked me out from making changes to my database unless I signed up for a paid subscription. FOSS or bust.
- vladharbuz 3y agoI hope they fix all the issues with unlocking. Sometimes it takes ~20sec to unlock 1Password. Sometimes unlocking the browser plugin causes the app to pop up, other times not. Sometimes it just doesn’t unlock. I think there are two kinds of browser extension, which is confusing. All very frustrating at times and only getting worse.
- KomoD 3y agoI don't like telemetry but I'm a happy 1Password customer, will probably opt-out anyway.
- Nicksil 3y agoThis is very simple: Present a one-time prompt asking to opt-in. Explain to me how my admittedly naive solution fails to deliver for all consenting parties.
- Entinel 3y agoIt doesn't deliver for the company. Opt in telemetry is the same as not doing telemetry. Not because people are morally against telemetry but most people just click through. You might say that is a good thing or that is how it should be but that is exactly why it doesn't deliver the desired result for the company.
- bwoodruff 3y agoI wrote more about the consent aspect here: https://news.ycombinator.com/item?id=35706897 https://news.ycombinator.com/item?id=35706897 tl;dr If we roll this out to customers, we'll be asking for consent, and won't be collecting telemetry data unless we have it. -Ben, 1Password
- smileybarry 3y agoIt sounds like they're planning it to be as general as possible (more just "how much is each feature used"), but it'll also be fully opt-in: > And, of course, once this functionality rolls out to customers, you’ll be able to control whether or not telemetry is active on your account. ("account" sounds like you can turn it off family-wide or even organization-wide) [ Reposted my comment from duplicate post: https://news.ycombinator.com/item?id=35685170 https://news.ycombinator.com/item?id=35685170 ]
- einherjae 3y agoExplicitly opt-out sadly. It bothers me quite a bit to read that we’ve normalized telemetry as much as we have. If you’d asked more or less any random hacker 10 years ago if any of this was remotely OK they’d all be slack-jawed to learn what has happened. Where did all the privacy conscious hackers go? Did they all get replaced when JavaScript and Electron became the norm?
- bwoodruff 3y agoI wrote more about the consent aspect here: https://news.ycombinator.com/item?id=35706897 https://news.ycombinator.com/item?id=35706897 tl;dr If we roll this out to customers, we'll be asking for consent, and won't be collecting telemetry data unless we have it. -Ben, 1Password
- squeegee_scream 3y ago> Over the years, we’ve relied on our own usage in conjunction with your feedback to inform our decision making. This presents a challenge, though: we don’t know when you run into trouble unless you tell us. And sure, we have an extensive user research program, and listen to all of the feedback you share online and in conversations with our team. > But there are millions of people using 1Password now, often in cool and innovative ways! If we’re going to keep improving 1Password, we can no longer rely on our own usage and your direct feedback alone. I wish I were in the room when these arguments were being made. I would like to see the data that led them to this conclusion. I used to work at 1P, I was a happy user before I started working there and I continue to be a happy user. But I can remember so many conversations about telemetry and how we’d never use it…
- nickstinemates 3y agoThe quote isn't a reflection of the conversation they were having; it's merely a justification they're using for the decision they made.
- raverbashing 3y ago> But there are millions of people using 1Password now, often in cool and innovative It's a password manager, what's "cool" about it? 1Pwd always rubbed me the wrong way in the way they "take themselves too seriously" and overrate their importance It's a password manager. They wouldn't even sync to cloud at first iirc, no? The more boring the better
- themagician 3y agoYou can use it for a lot more than just passwords, which IMO is what makes it stand apart from Bitwarden. You can store notes, credit cards, photocopies of IDs, software licenses, key pairs, etc. You get 1GB of storage. They really have turned it into a "vault" for anything digital.
- tweetle_beetle 3y agoFairly sure Bitwarden has done all that for some time. Having had to use both at work, I can't see any killer features that 1Password has in my use case and there are various small things that slow me down when using it.
- rdl 3y agoThe 1Password "no local/standalone vaults" "upgrade" in 7->8 is what got me to leave it after 15 years or so. They're killing the extensions used by Chrome/Brave/etc. in 3 months, so it became critical to move off Version 7 (which is probably not getting much security maintenance now, either). RIP.
- ssabetan 3y agoThis is the issue I'm having as well. I've been a standalone customer that's been paying since 2007, if I can't host my own vault either locally or in Dropbox - I'm out. I was hoping to use 1P 7 for as long as I can, but with the Chrome extension dying it's going to become unusable. What have you found as an alternative?
- lgreiv 3y agoThis is my stance as well. I have not chosen a successor yet, but I’ll have a look at Bitwarden, Keepass and the recently released Proton Pass. Trusting Dropbox for sync (which I did) meant trusting a cloud service, too, but IMO it is a less lucrative target for hacks than a server that stores _nothing but_ credentials. Also, using DB made me less dependent on connectivity (LAN sync) and would let me switch providers quite easily.
- AwaAwa 3y agoI'm going to try KeePassXC & syncthing. I assume its going to be no where near as good as 1P, but between no extension support, no local vaults, secret security ops, I don't see a choice.
- kmfrk 3y agoI've had issues where 1Password wouldn't save my new logins properly, lasting for over a day. Maybe that's why they need the telemetry. Do 1Password do security/privacy audits the way Mullvad do? That's a pretty decent way of building goodwill over time when it comes to decisions like this. It's probably a fine decision, but they should probably have gone to greater lengths to write this blog post in more exhaustive detail.
- darknavi 3y agoIf they could use telemetry to deduce which websites were not auto-filling correctly then I'm all aboard.
- bwoodruff 3y agoI love that idea. We'd have to be super careful with the de-identification of associated data (which we're doing anyway), but having automation behind figuring out filling failures could be a huge boon. I'll share the thought with the team. -Ben, 1Password
- rdl 3y agoTelemetry in a "trust us, this closed-source application which contains all your secrets, which we provide you and which we update periodically, is only contacting us for "privacy protecting telemetry" and not exfiltration, intentionally or not, of your most sensitive of all data" application is a hard pass for me. This seems like an IQ test kind of question. (So many times error reporting, etc. have accidentally leaked highly sensitive data, which was then the source of a major compromise, in other systems. Maybe 1Password won't get it wrong, maybe 1Password will never be subject to any pressure to get it wrong...)
- hrunt 3y agoImagine for a minute that you have a hammer. This hammer is a very useful tool and you have never had a problem with it. You don't know what is in the hammer -- could be steel, could be titanium, could be uranium (you're not a scientist!) -- but you know that it has always worked for you. Your experience with the hammer is so positive, you would buy another hammer from the company again, without question. One day, the company that makes this hammer says that they will be updating it to automatically tell the company a bunch of information about the hammer's use -- when it's used, where it's used, what the environment is like around the hammer, how many times it's used, what it's used for. They assure you that they don't care about who is using the hammer, but obviously it will be YOUR hammer reporting the information, so at some level it will be associated with you. Why are they doing this? Well, they know that sometimes their hammers break. They only know this, though, because sometimes their hammers break for their own employees and sometimes customers tell them hammers break. They would really like to know ALL the times their hammers break, though, so that can try to fix all the problems with their hammers, and not just the ones they see or get reported to them. They say this will be best for their customers and that's why customers should be on board with the change. No one would ever buy that hammer again, right? Regardless of the privacy implications of the company knowing everything about your usage of the hammer, the company is basically saying that their hammers break so much that many of their customers don't bother telling them and just go use someone's hammer. In other words, their product is bad and their customers don't value it enough to deal with it. Don't even get me started on paying monthly for that hammer ...
- 35803288 3y agoThis is a big, hard NO. Bye bye 1P.
- AwaAwa 3y agoLock folk in with 'cloud' based 'subscription' models, and then do what you will. 'Climate change' in 'cloud' world.
- gaws 3y agoI've been a 1Password customer for five years. The move to 1password 8 has been beyond disastrous: terrible extension integration, browser constantly crashing when trying to log into the web panel, and the mobile app integration hardly works with mobile browsers. Add the recent announcements that the company will no longer support their last stable version -- 7 -- and move to using telemetry -- I'm out. I've jumped to Bitwarden; open source, cheap, and competitive features. It was a no-brainer.
- SomeHacker44 3y agoi have literally over 5,000 passwords going back almost 30 years in a dozen vaults in 1P. How easy was it to migrate to Bitwarden? Any issues with Windows, Android, Linux, i(Pad)OS with the move? thanks!
- RoyGBivCap 3y agoWow. I thought I had a lot with over 900. Mostly exported from Brave because I just started using a password manager less than a year ago.
- bombcar 3y agoI have 1100+ but I suspect many are "dead" or otherwise invalid/not needed, but there's never a reason to remove them (this is likely a source of metadata leaking someday, somehow, as it may indicate if you once had an account, etc).
- gaws 3y agoI can't speak for multiple vaults, but it was extremely easy for me to import my single vault: 1. Export 1P passwords to a 1pux file 2. Import file into Bitwarden 3. Done.
- stefandesu 3y agoHow did you deal with unsupported data types? As far as I remember, Bitwarden is extremely limited when it comes to that.
- sashk 3y ago> At that point, we’ll also provide guidance on how you can opt out if you’d like to. Well, at least there is opt out. Probably, will be on account-by-account basis, not family/organization-wide.
- torstenvl 3y agoUsers: We want standalone non-subscription licenses! 1Password: I really wish we knew what users wanted. Users: Please don't move to Electron, I don't want Chrome bugs in my password manager. 1Password: I'm just baffled. We never hear from users. Users: Please, for the love of God, give us control over our vaults. Don't go cloud-only, we're begging you! 1Password: Better turn on telemetry. It's the only way to solve this mystery for the ages.
- kspacewalk2 3y agoThey're focusing of the enterprise market. Those users are now what matters, because that's where the money is. Individual and family customers will still get their tier of product, but ain't no company-wide business decisions gonna be catered to their whims. And particularly with standalone perpetual licences, which I'm still clinging on to. Sync via DropBox, share a vault with family, and another one with my small team at work. It's perfect, for me. But it just doesn't work for 1Password, financially. No amount of getting upset or whiny will change that. Time to get over it.
- onehair 3y agoWhile you're free to get over it, I will stick to working with standalone software. I use KeePassXC + DropBox (or any other syncing tool) Ah, and no telemetry there ;-)
- yunwal 3y agoNot sure if the winky-face was sarcasm, but in case not, dropbox collects lots of telemetry https://www.dropboxforum.com/t5/Integrations/Why-So-Much-Telemetry/td-p/455961/page/3 https://www.dropboxforum.com/t5/Integrations/Why-So-Much-Tel...
- SanjayMehta 3y agoTo give 1Password some credit, they haven't broken the standalone licenses yet. Every time the iOS app updates, I suffer from an anxiety attack that sync via dropbox might break. Unsure about a reasonable alternative.
- VincentEvans 3y agoHow about an ability to resize the width of the column that lists the names of the secrets in the vault so that I can see what they are. That’d be higher on my priority list.
- samcat116 3y agoJust wanted to add my voice that I really like the newer 1Password stuff. I haven't had any issues I've seen people complaining about, and don't have any of the philosophical issues that a lot of others seem to have. If you're one of those people, you should be definitely just move to Bitwarden.
- santiagobasulto 3y agoWhat a coincidence. Just yesterday I was discussing 1pwd’s series A with a friend and I remembered about a podcast the founder (David Teare) did with DHH (Rework Podcast). In it, he literally cites this. He says they raised money for a bunch of things, and one, was to add metrics, but he wanted them to make them anonymous. We’ll see how it plays out. Podcast: https://open.spotify.com/episode/6RZm7V8IcvuMuaCmVBE4EG?si=vOQuSR2qT1SJQafB8unOZA&context=spotify%3Aepisode%3A6RZm7V8IcvuMuaCmVBE4EG https://open.spotify.com/episode/6RZm7V8IcvuMuaCmVBE4EG?si=v...
- latexr 3y agoLink on official website, so anyone can listen: https://37signals.com/podcast/venture-capital-and-control-with-david-teare/ https://37signals.com/podcast/venture-capital-and-control-wi...
- MojoLobo 3y agoAre there any password managers that provide a similar UX on mobile phones/iOS? If so, I'll move there in an instant. > At that point, we’ll also provide guidance on how you can opt out if you’d like to. Better than nothing. But they're moving away from being the #1 choice and a great product step-by-step...
- MaintenanceMode 3y agoThe writing has been on the wall for some time. It's clear that they are focused on growing the company and maximizing revenue. Nothing wrong with that, but my family's needs aren't going to satisfy a hungry capitalistic company. So I've had plenty of time to have alternatives, which I've been using. 1Password has been in parallel with another password manager and once they end support for 1Password 7 my family will turn this one off and switch. The experience with 1Password 7 isn't all that great right now anyway, so I'm not losing much really. The syncing is super useful, but there is a solution to that too. It's been a good ride. Now it's good riddance.
- climb_stealth 3y agoWhat have you been using as an alternative? Especially for a family use case.
- stereoradonc 3y agoThis is the killer feature I was missing! Pay money for usage and the way the app interacts with users, and they have crossed their hearts that they won't "spy" on us (which can change any other time in their terms and conditions). Who wants to bet they will find a way to stuff "privacy focused apps" in the vault? Why not?
- crossroadsguy 3y agoThey’re going CrashPlan. You were all dog-fooders and beta testers all these years for their eventual destination - the enterprise. Yes, of course you’ll be able to buy at $XXX/year with a minimum 10 users plan while you are all still singing paeans in the tune of - “oh it has gone shites, but it’s great, happy customer here!” Mac/Apple only customers have this strong inclination for some kind of Stockholm syndrome when it comes to software and devs going shitty and hostile. I find this weird kind of loyalty added to software as well that somehow starts as Mac only and that loyalty stays even after they go crap. Often blown out of proportion. I mean I always wonder what is the reason that these people don’t even want to acknowledge BitWarden.
- favorited 3y ago> Mac/Apple only customers have this strong inclination for some kind of Stockholm syndrome when it comes to software For decades, Mac users didn't have the same software choices that Windows users had, and a lot of what was available were shitty ports. When a company released high-quality Mac software, it was noticed and appreciated by Mac users. Obviously that situation has changed in a post-iPhone world, but the culture of appreciating when someone made a really great Mac-native app is still there for a lot of people.
- webworker 3y agoBitWarden was never the Mac-first native app that 1P was. I personally pay for BitWarden and never used 1P. Now I'm slowly migrating back to iCloud Keychain because I feel like I can't trust any of these 3rd party pw managers to not eventually throw us to the hedge funds.
- illiarian 3y ago> Mac/Apple only customers have this strong inclination for some kind of Stockholm syndrome when it comes to software and devs going shitty and hostile. It's exactly the opposite of what you wrote. Mac users abhor the software that turns shitty. However, as on all modern platforms, there's no choice: all software is turning shitty.
- deleted 3y ago[deleted]
- hankman86 3y agoThis is very, very bad news. Even if their client telemetry ends up being opt-in, the “feature” will be part of the client code base, opening up an attack surface and chance of data leakage. I can already see the apology letter from their CEO coming in (“we let our users down”). 1Password, don’t do it! Rely on other means to collect usability feedback like surveys, internal usability testing and developer tooling for build-time usability testing. Your app is simple enough that you absolutely, categorically do not need to subject your users to mass surveillance. I am currently paying for a 1P family subscription and I will be moving to another provider or self-host a free/OSS password manager should your telemetry plans eventuate.
- 6sp 3y agoI’m glad I’m not alone in my thoughts on 1P 8. Unfortunately it’s become completely unusable for me and I’m actively looking into alternatives. Leaning toward Bitwarden although it’s UI is a considerable downgrade imo.
- throwaway5959 3y agoThis is garbage. For an application so sensitive, telemetry should be opt-in if present at all.
- rcarmo 3y agoI’ve completely moved away from 1Password (here’s my list of alternatives: https://taoofmac.com/space/apps/1password https://taoofmac.com/space/apps/1password) Right now, the only thing I am missing is something that will sync with a KeePass vault and push TOTP tokens to my Apple Watch (as well as a couple of rarely used credit cards whose PIN codes I would like to have always available for emergencies). Other than that, if you’re not an enterprise customer I think OS or browser-based password managers (which now sync across machines and platforms and even have the ability to do TOTP, at least on the Mac) are finally good enough for end users. If you need to store software licenses, recovery codes, etc., KeePass XC is excellent for that as well, and available everywhere (and no, sorry, I don’t want to use Bitwarden because I don’t want to run a dedicated sync service for myself, or use anyone else’s).
- AndyMcConachie 3y agoI've never trusted any of these password storage services and only use KeePassXC. I remember having conversations with people years ago when these services were appearing and I told them that eventually these services would screw over their users. To my amazement people continue to believe that storing their most precious information(passwords) with a 3rd party. I truly don't understand. It's just too much risk exposure for me. Why on God's green earth would anyone trust some random assholes with something as important as passwords? I just don't get it. They're gonna screw you over. And they're gonna continue screwing you over because you continue to be their customer. Just recognise that and move on.
- Hackbraten 3y ago> Why on God's green earth would anyone trust some random assholes with something as important as passwords? You’re going to have to trust the app’s code no matter what. As long as encryption and decryption happens locally, how does a hosted password manager make a difference to local storage?
- Double_a_92 3y agoI honestly can't understand how anyone would use those cloud services for important passwords and keys. The risk/reward ratio is just too high. And for anything not crucially imporant I would just whatever my web browsers support natively.
- Hackbraten 3y agoIt makes using different web browsers easy. For example, Firefox on the desktop and Safari on the phone. I also don’t like the idea of locking password management into a specific browser because I switch browsers more often (last time 5 years ago) than password managers (last time 15 years ago). I don’t have an issue with passwords, even important ones, being synced with the cloud. As long as the crypto happens locally, and as long as I’m forced to trust the app developers anyway, what difference does cloud vs. local storage even make, security-wise?
- Double_a_92 3y agoA fully offline, and open source software can be audited.
- skylurk 3y agoWhat is the random query parameter injected into the open-and-fill feature? Is it not telemetry?
- latexr 3y agoIt’s the item’s UUID. You can verify this by using their `op` CLI tool and searching for the specific item.
- skylurk 3y agoGood to know. What is it used for? Is there a way to disable it?
- bwoodruff 3y agoIt tells the extension which item you've selected to fill. It isn't possible to use the Open & Fill feature without it. If you navigate to the website in your web browser and then fill from 1Password's inline menu, instead of using Open & Fill, you can avoid it. Hope that helps. Please drop us an email if you have further questions: support at 1password dot com -Ben, 1Password
- npteljes 3y agoI think it's ridiculous to have such functionality in a tool that's supposed to keep secrets. But we won't see meaningful change until a major WTF happens, and maybe not even after that.
- mieubrisse 3y agoUnpopular take: this is actually exciting to me. As development has continued, the 1P app seems to have gained in bugs. I've tried reporting these - I like 1P and the 1P team seems to care about delivering a quality product - but using their forums is very frictionful and I've often given up on reporting bugs because it's not worth the faff. Telemetry holds the promise that they can fix the bugs without me needing to manually report.
- roydivision 3y agoI’m counting the days before I finally need to find an alternative. I’m hanging on to the non-sub, non-cloud vault, non-telemetry version, but it’s only a matter of time. Shame because otherwise it’s been a great product, rock solid.
- Arubis 3y agoI really don’t want to have to deal with migrating fifteen years of stuff out of 1Password, but this might compel me to out of respect for the clients I work with.
- bwoodruff 3y agoHi folks, Thank you for the comments on this important topic. 1Password's mission is to help people safeguard their most important information and to do that, we have always taken a human-centric approach to security. In order to deliver the exceptional product experience our users expect from us, we need to better understand how they use 1Password. And while our goal is to deliver better 1Password products, we won’t require our community to help us if they don't want to. We're fully committed to transparency and will provide updates coming out of our research and development period. When we are ready for a wider rollout of this functionality, we will provide clear, in-app messaging, and you’ll be able to control whether or not telemetry is active on your account. In the meantime, thank you for sharing your feedback – these discussions are always valuable to us, and we appreciate your constructive candor. -Ben, 1Password
- 93po 3y agoUnless telemetry is opt-in, there is no commitment to transparency. Opt-out may as well just be buried as a disclosure in the EULA that no one reads.
- bwoodruff 3y agoAs our CTO, Pedro, discussed in his blog post (https://blog.1password.com/privacy-preserving-app-telemetry/ https://blog.1password.com/privacy-preserving-app-telemetry/), we have only rolled out telemetry to our employee base. We will be analyzing the results of this internal-only roll-out before implementing this functionality more broadly. This functionality will have a prominent in-app message that will ask Individual and Family account users to choose whether they prefer to keep telemetry on or off their account. Nothing gets collected until they’ve made this choice, and users will be able to change their preferences whenever they would like. -Ben, 1Password
- 93po 3y ago> This functionality will have a prominent in-app message that will ask Individual and Family account users to choose whether they prefer to keep telemetry on or off their account. Nothing gets collected until they’ve made this choice, and users will be able to change their preferences whenever they would like. Does the choice for "Track My Activity" look like a "Continue" or "Next" button? Respectfully, it sounds like you're trying really hard to not actually say it's going to be opt-out.
- desmondrd 3y agoI've used 1Password since 2014 -- almost 10 years! And my company uses it, so I'm both personal and business user. Product quality, especially with 1Password8 has deteriorated significantly. A big bag refactor to electron with no telemetry is probably the root cause. Not necessarily poor strategy, but certainly poor execution. Telemetry is actually a good thing for 1Password users who see product quality decreasing bc it gives the PMs there some information to go off. The product surface area is huge now, and it's natural to lose sight of the most important stuff. If I was in charge, what would I do? 1. Introduce telemetry and get data into hands of PMs + Designers 2. Pause all new feature development until table stakes features are working flawlessly: 1Password opens under 200ms for most users; auto fill in Chrome + Firefox actually F*king works like it used to before v8. 3. Trim down product surface area by killing features. E.g. decide is the default UX for auto-fill based on interacting with a button inside form inputs OR simply hitting the keyboard shortcut to autofill? Kill the other bc the interaction between these choices is painful. I'll give them a year to figure this out. In the meantime, a Copilot / ChaptGPT enabled bootstrap founder will come along and build out a trimmed down version with just the basics and start eating their lunch.
- 1123581321 3y agoThere are already a bunch of competitors out there, and some of them seem to have been built quickly. Might be worth checking out if you've become this unhappy with 1Password.
- TheRealDunkirk 3y agoUS companies, led by VC's, have mastered the art of "shimming" themselves into every consumer interation possible, and then expanding that shim until all we can do is give up and say, "I guess that's just how it is," cede our privacy to yet another 3rd party, and pay $X/mo for the privilege. It's exhausting. Meanwhile, it seems almost everyone in Congress is making BANK on insider trading, probably cooperating with private equity doing this sort of thing, so there's no chance to implement regulations to prevent people from boiling more frogs. If there's one app or service that I use which isn't doing this, I don't know what it would be. Maybe Sublime Text? It's the only thing installed on my computer that I trust to not be transmitting telemetry. I guess that means I should join a VC firm and convince them to do a big investment in it to make it a be-all-things-to-all-people golem like VS Code, and include telemetry and a monthly cost model. We're running out of things to enshittify people!
- TheRealDunkirk 3y agoI’ve resisted putting my passwords in Apple’s keychain, because it’s the last “egg” I DON’T have in their “basket,” but I think 1Password has finally turned up the heat a bit too far on this frog.
- csubj 3y agoFor every person here reading and commenting, please also share your opinion with the support email they provided: support+telemetry@1password.com I have low confidence they will listen, but might as well try.
- replwoacause 3y agoGlad I never moved to 1Password. Been a happy Bitwarden customer for years.
- piperswe 3y ago1Password's recent developments are sad, especially so since I don't know another fully-featured secrets manager I can wholeheartedly recommend to less tech-savvy folks. Bitwarden's UI is nowhere near as polished and end-user-friendly as 1Password's IME, and the password managers built in to phone operating systems manage passwords - nothing else. Also, 1Password's sharing functionality is invaluable - if I want to share a credit card number or something with family, I can just put it in a shared vault. Is there another user-friendly, powerful password manager out there that I can recommend instead?
- openplatypus 3y agoHey 1Password, make sure to set Telemetry as Opt-In ONLY in the EU. You know. Laws and compliance stuff.
- ___dam___ 3y ago1Password is the leading cautionary tale of how to make boat loads of happy customers cry in the shower daily. They took an amazing product that worked better than every competitor and was easy to use then ruined it with the absolute dumbest product decisions I've ever seen. They gave Apple the green light to put them out of business and I'll be switching as soon as that feature is available. Their product decisions were almost as bad as Sonos, almost.